Skip to content

[27.x backport] vendor: github.com/opencontainers/runc v1.1.14#48430

Merged
thaJeztah merged 1 commit intomoby:27.xfrom
vvoland:48425-27.x
Sep 4, 2024
Merged

[27.x backport] vendor: github.com/opencontainers/runc v1.1.14#48430
thaJeztah merged 1 commit intomoby:27.xfrom
vvoland:48425-27.x

Conversation

@vvoland
Copy link
Contributor

@vvoland vvoland commented Sep 3, 2024

diff: opencontainers/runc@v1.1.13...v1.1.14

Release Notes:

  • Fix CVE-2024-45310 / GHSA-jfvp-7x6p-h2pv, a low-severity attack that allowed maliciously configured containers to create empty files and directories on the host.
  • Add support for Go 1.23.
  • Revert "allow overriding VERSION value in Makefile" and add EXTRA_VERSION.
  • rootfs: consolidate mountpoint creation logic.

diff: opencontainers/runc@v1.1.13...v1.1.14

Release Notes:

- Fix CVE-2024-45310 / GHSA-jfvp-7x6p-h2pv, a low-severity attack that allowed maliciously configured containers to create empty files and directories on the host.
- Add support for Go 1.23.
- Revert "allow overriding VERSION value in Makefile" and add EXTRA_VERSION.
- rootfs: consolidate mountpoint creation logic.

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
(cherry picked from commit b5ec31f)
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com>
@vvoland vvoland added this to the 27.2.1 milestone Sep 3, 2024
@vvoland vvoland self-assigned this Sep 3, 2024
@vvoland vvoland requested a review from thaJeztah September 4, 2024 07:47
@thaJeztah
Copy link
Member

Yup; LGTM, but mostly to please the scanners, because I don't think the code-changes are strictly needed for what we use.

Copy link
Member

@thaJeztah thaJeztah left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@thaJeztah thaJeztah merged commit fefdb1b into moby:27.x Sep 4, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants